RE: [PHP-DB] PHP security
| From: | Ben Cairns | Date: | Wed, 21 Feb 2001 10:05:46 +0000 |
| Subject: | RE: [PHP-DB] PHP security | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-6822@lists.php.net to get a copy of this message | ||
Anything contained within the PHP open & close Tags (<? ?> ) is parsed out
server side.
In order for them to read the source of the file, they must have console
access.
Try and get a password from www.mywapfone.net/index.php
That page does a DB connect using your script.
You cannot see my Password in the source right?
Does this answer your question?
As the MySQL server is on localhost, then the password never leaves the
machine, so is not travelling over the internet.
Therefore, no-one can packet grab from the machine to get the password.
-- Ben Cairns - Head Of Technical Operations
intasept.COM
Tel: 01332 365333
Fax: 01332 346010
E-Mail: BenC@intasept.com
Web: http://www.intasept.com
"MAKING sense of
the INFORMATION
TECHNOLOGY age
@ WORK......"